Short Name |
TCP:C2S:EXPLOIT:C2S-URG-OVERLAP |
---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop Packet |
Category |
TCP |
Release Date |
2003/04/22 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This protocol anomaly triggers when it detects overlapping urgent data. While some protocols (like FTP) use the URGPTR flag in the TCP header to signal out-of-band data, it is rare to see overlapping urgent data. This can be an evasion attempt.
TCP datagrams containing overlapping URGENT data, or a set URGENT flag and overlapping sequence numbers constitute a protocol anomaly. The condition could indicate that a data transmission error has occurred, or that an attack involving the injection of malformed datagrams into the network is underway.